May 1, 1982 · TAP
TAP No. 75 - 11th Anniversary Issue: WATS Extenders

Marking TAP’s 11th anniversary, ‘The Magician’ explains how legitimate corporate WATS (Wide Area Telecommunications Service) systems, originally built to link a company’s inbound 800-number sales line to its outbound long-distance line for traveling salesmen, were repurposed by phone phreaks as free long-distance relays once companies stopped using them after hours. The article frames blue boxing as increasingly risky due to Bell’s improved detection (CCIS) and describes how WATS extender abuse is tracked through itemized call records, cautioning that unauthorized use constitutes theft of communications services and that phone companies actively assist investigations once abuse is detected.
WATS EYTPNDERS
the Magician
Many people think cf phone phreaks as slize,
out to rip off Bell for all she is vorth.
Nothing
could be further irc the truth !
Granted, there
are some vho get their kicks just by making free
calls, however they are not true phone phreaks.
Pe
phone
phreaks
‘are
"te leconmunications
hobbyists" who experiuent, play vith and learn
from
the
phone
systes.
Occasionally
this
experimenting, and a need te communicate vith
other phreaks (vithout going broke),
leads to free
calls. The free calls are but a small subset of a
"RUF phone phreaks activities.
Until several years ago, The phreaks main
tool for
free
calls vas the Blue Box.
In recent
years hovever, Bell has made GREAT strides in
their security and detection of Blue Box's. While
Box's still work, their use is becoming EXTRPAELY
dangerous. With the advent of CCIS, the places
where a Blue Box vill werk are rapidly decreasing,
and within several years the Box vill be totally
obsolete.
Thus for their communications needs, phreaks
have turned to other sethods, one being: WATS
FYTENDERS,
Kany companies
thrcaghout the fMnited States
have salesman in the field that must contact a
large amcunt of customers long'distance by
phone.
70 pay for these calis, generally the sale
the companies Bell credit card
(Nov
ci
"Calling Card") this is quite expensive to the
company.
Several years aqo, someone case up vith a
neat money saving idea. Since the company already
has an INWATS (800) number fcr salesman to call in
orders to the main flant, and since the compnay
had a flot rate OUTWATS line to call customers
during the day. Why nct couple them together after
hou s so that
the sal.
m
calls the
cospanies
INWATS 800 number, then gets connected up to
OUTWATS. This vould sean he could call anywhere in
the United States,
fros anyvhere at no charge to
him!
"his arrangement veuld save the company
tremendous agounts cf long distance charges since
they had the WATS lines anyvay, and the WATS vas a
lot sore cost efficient than Credit cards.
This arrangement vas exactly hov early “WATS
YYTENDFPS" vorked.
‘ During WATS (800)
scanning (Por how to 4o
this, read "Napolean Solo's" EXCELLENT article in
issue 55) phreaks discovered these WATS EXTENDERS,
and found they could call anyvhere in the country
just hy calling the extenders 800 number, -then
(Using "ouch Tone of course) dial the number the
vanted.
The companies
socn realized
that their
extenders vere being messed vith and decided to
add some security to prevent tampering.
Tt was set up so that when a salesman dialed
the WATS EXTENDER, he would here what sounds like
@ ial tone. The salesman then keyed in a four
digit Touch Tone secret access code. If the code
vas incorrect a high-low tone vould result, and
the extender would have tc
be re-dialed. If the
code vas correct, a second internal BY dial tone
would result. The salesman would then access the
companies OUTWATS line hy hitting an 8 or 9
(usually) an@ dial wherever he vanted.
The four digit access code posed a problem to
Dhreaks since only 1 out of 9999 possible codes
vorked, and the 800 nunber had to be re-dialed
each time to try ancther.
Nany a
Phone Phreak spent
long nights
breaking the four digit codes and then using the
extenders thesselves! nost companies change the
code every fev sonths so the phreaks vould have to
start over again.
(Also cospany
employees tha’
vere not authorized to knew, but found out from
leaks")
.
Bany of you have frebably heard of the
in
us
computer
"Charlie".
Yor
those who
haven't, several years ago Charlie was brought to
life by
Capo Crunch (Wow retired
from the
Communications service) Charlie was an APPLE IT
computer vith a special board which alloved it to
Touch Tone dial nuabers extresely rapidly (£/A)
then "listen" to the results (A/D).
Charlie was fut to use calling a given WATS
EXTERDER, trying an access cote, if the high-low
tone was heard (meaning
an incorrect code),
Charlie hung up and dialed again, trying the next
sequential code.
Charlie vould sit vorking for
hours, and vhen it fcund the code, it vould print
it on it's display screen. VERY ®ffective t
S4
“ae
147 W. 42 St.
New York 10036
2
ga
X
Pe!
mer
TAP
Room 603
.
y
11th ANNIVERSARY ISSUE
MaY-JUNE
§=61982
Unfortunately the only problem vith Charlie
vas that he vas very noticeable to'Bell. every
tine an 800 number is called, an AMA record is
Punched at the C.O. thus it looks real phunny to
Bell to see that you have called pry dock orange
shippers 800 noaber in Plorida 3,750 times at 2:00
AB with each call lasting 1 second ! Since Charlie
vas not very easily pertable to pay phones this
was a reel probles.
There are many WATS EXTENDERS reportedly
presently in service. fost working as described,
vith some taking more then a four digit code, and
Some even respondina te voice input |
It should be pointed cut hovever, that should
any of you crack any WATS EXTENDER access codes
and attempt to use thes, you are guilty of Theft
Of communications services from the company vho
ovns it, and Bell is
very villing and able to help
them nail you!
WATS EYTPNDERS can get you in
avery bit as wach trouble as a Blue Box should you
be canght.
Rost WATS EXTENDERS also record all nusbers
called from them on ODTWATS.
If the company
detects the extender being ais-used, they will
usually first try to change the access code. If
the abuse continues and they get
mad
enough they
will contact Bell who will help them investigate
all the nuahers you called !
Thus, as in sost things those of you vho are
@etermined to play with WATS EXTENDEPS, do so from
a
pay
phone
and
only
to
institutional
switchboards, or people vith short memories. By
the way, on some "Honey First" payphones
(as
Opposed to "Dial Tene First") the Touch Tone pad
is cut off after the WATS call is complete.
(Because
of polarity
reversal)
It can
be
Te-activated
by
depositing a
dine after the
connection is
made, which you vill get back after
you hang up.
Also please remember the opening of this
article. DO NOT use WATS EXTENNERS just to
free calls all the time!, experiment with them
and
learn vat they can do and how they work. I think
you will learn a lot It
Send any ce
ents etc. to:
TAP C/o The Magician
to cute rou want .
cut out
this chart.
CBae Tete TeeS Fe eT
ee
No. 75
ck Issues are $.75 each. Issue 950 is $1.50.
Subscriptions - 10 issues - US Bulk Rate $7.
t
VGs"Butk
Envelope Rate $8
US Pirst Class in plain sealed envelope $10.
| canada ¢ Mexico rirst
Class
$10.
:
I
Foreign Surface $8. - For gn Air Mail $12.
'
| ZMPORTANT! Please include your mailing label or a
Xerox copy whenever you write to TAP about your
|
subscription,
|
Blectronic Courses - §.75 each. A - DC Basics,
tl
leas Be paste, C= Phone Basics, D - Amplifiers.
*]
Be!
a
-
+50.
TAP "l0th Anniversary* Pen - $.50.
| FAB Cassette rape -
$4. Hear Capt Crunch. Al B 11, 9}
Toe
Engre:
& Bell Security Chief John Doherty.
[ FAP Fact Sheet #1 - $.50. Credit card call hint
TAD
| aE
ck
Ghest $2 - $.50. Pree BELL phone calls.
‘TAP Fact Shee!
- §.50. Pree GTE phone calls.
FAP Fact Sheet #4 - $.50. Dual Tone Oscillator,
| Displayed Red Box, & 2600 Whistle Perfector plans. §
Send CASH, check, or money order to :
FAP, Room 603, 147 west 42nd Street, New York,
E
ALARMS
F. I'm sure many of you tiave read about burglars
ripping off a jewlry exchange or such and bypassing
the alarm with a blackbox (not in our terms ),
In
the following series of articles I will explain
how (to the last detail) these alarms work and
how they are fucked by the pros. This first article
is about sensors.
Sensors are located in 2 general places.
ance ways and in frequently travied areas.
lets take a look at doors. One tyve of door
sensor is the magnetic switch, which is located
on the side or top of the door.
The illustrations chow
two basic swithes and their
placement. To bypass them
you must determine wether
it is a closed or open
circut. Take a VOM and
test the terminals for
a current flow. If you
In entr-
First
P as
s
—
Switch
dort get a reading then
test for aX closed circut.
Never test with an ohms range first because if
it is on open circut you will set it off. Alvays
use a voltage range first.
If it is normaly open just
cut one wire. If it's
normaly closed short the
-wires. Never attempt to
vypass then with a magnet as
sone of them are papetionlty, od
=
biased and you will set
them off. Magnetics are also placed
inside door frames and on
the inside of rarage doors.
The bert way to check for
mamnetic swithes is a
metal detector.
The second type of cwitch
is a push button located in the frame
of the door. To bysess them a rtiff p
of metal is slid between the frame and door
and is used to hold the swith down as the door is
ovened. By the way, this is also used in lavatories
to automaticaly flush the urinals,
Windows are the next topic. They are usually
protected against breakare only. This
is done by placing a loop of thin
Vibrmtion Sensor,
Switch
rains Doe Svs
metallic foil on the window. If it's
emashed the foil is broken and the
alarm is sounded. (To fuck it ap
take a razor blade and cut a line
across it. It is invisible and the
alarn sounds as soon as it's turned
on.) Just
use a rless cutter and
cut a section out of the dass. Then
reach in ané short the contacts,
An in-
teresting vay to break windous is to
cover the gdacs with tave. Then the
window is rently tapped with a hammer
until all the rlasr is broken. Then
pull the tape off in a single cheet
and the broken hase will remain stuck
to it, The latest in window and
wall protection is the vibration sensor.
There is no fool prufe way to fool
them (yet). Vibration sensors are also
used on fences to detect climbinr.
If possible it is alvays best to
simply avoid the sensor than to try
7?
“ei
to bypase it. Another type-of device
Protects
Walls & Ceilings
is the old preasure mat. They are
.
used under carpets or as door mats.
UU
Placement is in halls,stairvays,
under windows and in front of doors.
The only way to avoid them is to walk
along the edre of a suspected hall and
avoid all welcum mats. Light beam detect
ors use a bean of lirht that sets an ala
rm off if the bean is broken. They use
IR, UV and visible lirht. Look for
small boxes with windows at about thirh
level. They are now mounted in other
fixtures such as sockets and books.
Vibration Detector. .
can be filled with any substance you
choose ) and fill it with flourescent
paint ( at any novelty Store or Edmund
Boientitio )
x eo
Switch Placement
The
‘best way to locate a visible light.beam
is to get a can of dry powder deoderant
and spray it in the direction you are
going. The beam will show up, just
like a flashlight in a dusty room. For
UV get a "empty" spray can ( a can that
Bispy Passive Infrared
Most places use IR. The only way
to IR is a IR scope which is expen—
sive and bulky. There is another
type of IR censor called passive
IR sensor. It notices a increase
in IR energy in an arep. ycuch as
the introduction of a human body
(live). They are disguised as wall
vents or sockets. Ultrasonic and
nicrovave detectors
use the doppler
effect to detect motion, just like
‘The only difference is that
sonar.
ultrasonics are more prone to false
alarme
due to chanres in
weather and
air current
ney look like small
table radios vith a larre vent
two small holes. They are a:
on vall mounting brackets as shown in
the picture.
‘The: Stainlece Steal Rat
IBM TIME SHARING OPTION (TSO)
Nick Haflinger
I have seen articles about computer access
but I almost never see anything about the GIANT
of computing.
IBM mainframe computers allow the
knowledgable user to do almost anything he
desires.
These huge machines are used by most
major corporations and nearly all utilities,
ingurance companies, and newer Social Security
offices.
Almost every computer has at least 1
dial-in port which can be called by anyone that
gs,
knows the number.
Some even have am Inwats line.
CAPITALIZED words are Keywords keyed in by
the user, that's you.
All system responses will
be capitalized
and enclosed in quotes, A dataset
Rane on TBH systems must be enclosed in single
apostophes (') or belong to the user. Get a note
pad ready and let's go
IBM systems have a monitor program called
Tso.
This is what we will be accessing, After
your terminal (110-300 baud) has made its
gonnection type in LOGON or //LOGON.
You should
be prompted for USERID, PASSWORD, and maybe
ACCOUNT NUMBER.
If you know all’the info just
type LOGON USERID/PASSWORD ACCOUNT NO.
Some
installations allow the use of nonsense like
LASTNAME/FIRSTNAME or similar constructs for
USERID/PASSWORD. Try calling the company and
obtaining the names of some programmers under
some pretext.
Try these names or use more
sophisticated wiretap procedures to obtain
actual.
userid's
Let's assume that you have gotten logged on
The system will reply with some messages and
eventually say "READY".
You are in!
Here are a
few commands that you can use to get your
bearings. Copy doun the reply to every command
you try.
If you have no experience with IBM
Zommand syntax the HELP command will be useful.
You may want to route this output to a printer
nter HELP HELP to get more information on the
help command.
Enter HELP by itself to get a list
of available commands.
Enter HELP COMMANDNAME to
get specific info for a command, eg, HELP EDIT
Will tell you about the edit command
Now on to the real goodies. When
logged on the system may h
iisted
datasets that belong to your userid.
use these as a tool for breaking the
Study the commands below and then we
discuss a general strategy for using
information that they will give us
you got
some
We want to
system
will
the
LISTCAT - Lists all the datasets owned by
your userid.
The system will also
{ell you what catalog the datasets
‘dsname*
Get the dsname from the
above command and this
will tell you the
Characteristics of the
dataset.
This i3\a good one. When you
Logged on
the system allocated
several datasets to your
terminal. They may contain
anything “so they are. the
starting point.
Copy doun ali
oF ENS! EP you see kstSt uns
your igt'you hit, the
jackpot. S¥S1¥ “anything ic
2ysten dataset and’ usually
ohlvables
This Will Ligt any jobs that ma
executing under your usersd:
Follow
tithe "Se"Zor more info.
-"this "will display the
characteristics of
your userid.
These can be changed during your
logon, Session but should be Changed
back before you logoff. It will B
helpful to have the options PROMPT
and MSGID. Tf you don't have them
just set them lip by entering
PROFILE PROMPT, ete.
LISTDS
LISTALC ST
Is
Xs
5
=
ave
OTe
a
STATUS
PROFILE
That's all for this month.
commands and if you can, get
command syntax via the HELP col
issues I will introduce more co!
Try out these
listing of the
.
In future
ands and teach
you how to enter programs into
the system
tventual
goal will
be to gain access to
password dataset and other goodies
Hew Economic Policy
Tired of all that bullshit the government has
been giving about how to reduce inflation? Well
here is the real way to cut your bills.
I Super—Markets
The next time you visit your local food rippéf
center that claims to have the lowest prices in
town, you can make sure that they keep their promise.
When you catch an emoloyee loafing on the job
vorrow (permanently) his or her little price tag
un. After several minuets of examination and
trial you can stamp your own prices just like
the pro. Need I go further? Of course. Just
for good relations take all those funny little
rolls of stickers that are ured to show vhen
there isa special and all the blank rolls for
the tag run. Beware. Make sure that the product
you stamp vith your mun is the same as the tag
fe. Some tage are pre labled: Grecery, candy,
milk item, etc. Hake sure the tar matbhes the
item. Never remark itens that are conmon. Many
times the cashiers know the price. Also, with
your "speciaP stikers be careful. Many times they
are distributed by the manufacturer of the product.
If you ere in a hurry just take the price tag
off the cheavest bargin brand and put it on the
best cuality brand. This can be tricky if not
impossible because some >laces have price tags
that are pre-cut, so they fall apart if you try
this.
II Counter
Espionare and Other Tricks
For all you that shoplift ( or about to bein)
here are some tips.
- stay avay from large Walls and Shopping Centers
it's like narc city. The narcs like it there
decause they can bust little kids for shoplifting
canéy.
= keep your eyes open for mirrors, two way mirrors,
cameras and nosey clerks.
- if you are with a partner keep your mouth shut
They have hidden mice in those tall columns that
seem to hold up the roof.
~ Avoid all large cilvered objects. In one place
I ‘now they put small cameras in larre silver
Christmas balls ( Merry Christmas, huh? )
- Look for peonle that you always see in the
same store and for people who walk around like
zombies and pay mare attention to the people in
the store than the products.
= avoid all people with 2-vay radios. They are
nost definitly not hams vith their 2 meter.
If you decide to shoplift (naughty you), remember
all you have to do is remove the item from its
package and take off all store mgy¥inrs and tags
and they cannot prove the item is yours. Use
dicplay models if possible, because you can fiddle
with them without suspieion. If you think the risk
of retting caught is too reat or you cannot
ret it because of its size ( I know a guy who
shoplifted a 20" crock pot ) you can etill get
it at a rreatly reduced price. Many places use
felt tip markers or pens to show reductions. When
a store has a clearance sale just cum on in and
make your own reductions ( not too outragous pleas}.
Sometime the cashier vill be suspicious and go and
chek your items price against one on the shelf.
‘The only vay to beat this is to mark all the itens
gown. Thie way you can also buy ceveral and you
do a publik service for their regular customers.
My last trick is to use a hirh quality eraser
and erase the first dirit of the price. I have
done this one several times with chips and other
expensive parts. Some of those clerks are as
Dlind as riveted bulkheads. The real price was
stamped on the package right next to the erased
price tag. I etill saved 10 Amirikan (worthless)
dollars.
Happy budget cutting 1
The Stainless Steal Rat
ATTENTION -
'- ATTENTION ---- ATTENTION
The 8BBS dial-up system mentioned in
TAP #72 is no longer in operation.
Last
summer while the SYSOP was away on
vacation his place was raided by the FBI,
police, Telco security and others.
The
8BBS disk packs, user log printouts and a
modem that some Philadelphia area users
had sent out were seized as evidence and
are being used to prosecute some people
in the Los Angeles and Philadelphia area.
In issue #71, I talked about the four major
alternate nets serving the country..I recieved some
letters from readers with info and comments. I'd 1
like to thank “It, Bill and you others for writing
to me. You were all helpful. SP Sprint, ‘CI, ITT
citicall, and Western Union aren't the only nets,
there are a lot of others, But they are the four
major ones that serve the public. Since they
serve the public, they are much easier for thé
average phreak to get access numbers and codes
for, But there are many other nets, as was pointed
out to me in a letter. If you have info on another
net, send it inl .
Also, I was told that I gave the impression
that Sprint covered most areas. All the alt. nets
are the same, in that they only cover the large
metropolitan cities, and sometimes local suburbs.
Thats where all the money is, and thats why they
can sell line time cheaper than ita Bell, ‘fa Bell
has to charge higher rates in the cities to subsi-
dize all the rural places where there is only one
phone in 10 square miles. The alt. nets only serve
the high volume aress, that is,
large cities.
Still, Sprint covers more cities than anyone else.
I have spent time since my last article
breaking into various nets, and can report that
“CI is ty far the easiest. In fact, I was able
to crack 3 codes in 30 minutes by hand, while
talking to my roommate and listening to Pink Floyd.
I had very little luck with Sprint, getting only
one code. IT? is a little easier than Sprint,
but I didn't get much there either. Western Union
covers so few cities, its hardly worth breaking
into,
If you have a computer with an autodial
modem, you can program the computer to break codes.
But- there is no modem that I know of that can
tell whether a phone is ringing or not, that is,
whether the call went through or got stopped.
But I got a great idea from a friend. Instead
of sitting by your phone and listening as your
computer runs through possible codes, program it
to dial other computers through the net, and let
it wait about 15 seconds after it finishes dialing
each time, and see if it gets a carrier. Then the
computer can tell by itself whether or not it has
hit a good code, and you can go drop acid or whate
ever you do in your spare time.
But whenever you are breaking codes, make
sure that the number you put in is a recording or
a big company computer (like TELENET), not your
girlfirends house, as the nets may wonder what
all this activity is and try to call the number
you are using, to see who lives there, who would
be calling them illegally, and generally hassle
them.
I also wouldn't worry tco much about the ness
tracing you, unless you are in their exchange. I
call in from home sometimes. What I would worry
about is them paying a little visit to the person
you have called, and asking who they know that
would be calling them at a large discount. So only
call instant amnesiacs, and not your grandmother.
If you really want to be safe, call through
one net to another net in the city you want, then
go through the second net to make a local call
to your friend. The second net will only be making
a local call, and so won't worry much about it.
The first net will only be able to trace to the
second net. Make the pigs work to find out who's
screwing them over! But be sure not to use the
same net twice in a row. Setting up various links
of the call through various nets, sort of in series,
is a great way to make alt nets safer. Unfortunately
it seriously degrades the quality of the final
line you have to talk over.
To change the subject, I have noticed that
some fire engines have big strobe lights mounted
in the front, near the cherry lights. I found out
that this is so that they can turn stop lights
green. “any stop lights have photocells that sense
incoming light to see if it is flashing at the
proper frequency, If it is, then all lights on the
side the strote is coming from are turned green ana
all others are turned red. Anywhite strobe light
should work, its the frequncy of the flashes that
gatter. I don't know what they are. But I do know
that you need an awfully big strobe light, about
the size of an airplane landing light it seemed to
me. They are probably expensive, although you may,
be able to get them cheap in a surplus store. I've
seen this system in Anchorage, San Jose, and San
Diego. I'm sure that many other cities have in-
stalled it on their major lights too, but check to
make sure your city has it before buying a light.
Have phun phreaking and F.T.B.S!
COMPUTER SECURITY
and the breaking thereof
By Simon Jester
PLASHICUUAUCLESUUUCSERPE2E22
00
There is a new method to break into computers,
and it has professional security consultants
shitting in their pents! In september 81, some
atudents at UC Berkeley discovered a way to break
into UNIX systems. One of them must have been a
real
asshole, because he told the system operator
who told
the system manager, who hired SRI to look
into it. SRI is Stanford Research Institure Inter--
national, and among other things they specialize
in computer security. At SRI Donn Parker looked
into the matter. Donn Parker is one of the top
security experts in the world. He looked into the
matter, and promptly realized that it compromized
all security on the UNIX. He also speculated that
the method could be adapted to work on other
systems, a5 well.
UNIX is an operating system for DEC computers.
I'm not sure if it works on other machines, but I
have heard that iia Bell uses a lot of UNIX systems.
The scam goes like this. On large computers, they
use a technique called time-sharing to.let a lot
of people use terminals all hooked up to one cent-
ral computer all at the same time. Each person is
assigned a portion of on-line memory (as opposed
to disk memory), which is called his’ work space.
The system saves a work space for itself, too.
‘The students discovered a way of having one termi-
nal take over control of another terminal and the
workspace that goes along with the second terminal.
The good part comes in here. ‘ost students and
hackers have low security accounts. But when you
take over another workspace, the person logged on
may have a
high security account. If
so, you could
go through his account and access all the high
security stuff he has access to thet you're not
supposed to have access to.
Cniy a few technical details on how to do
this are known.It is known that you somehow send
control and/or escape characters from your terminal
through to the other persons terminal and/or work-
space to take over control. This will work on UNIX
systems, and there
is some very similsir method
that may work on many other systems. Parker has
said that the only effective ways of fighting this
scam are to either remove the control/escape keys
from all terminals or to insert software filters
to filter out control/escape keys before they
reach the 0S. These are pretty lame solutions.
Con game in the cards?
‘A New Jersey man was Indicted yesterday on chirges of spe:
Ahan $22.000
is rad sevrices through
illegal use
af credit cards obtzin.
ef while In fail, The indictment by a federal eranc
Inry in Newark
charced
Riabert ‘Lee
Johason with four counts of mail fraud
CH
Interstate use of fraudulently obtained credit
"The governovent charged that Johnson
mpanies between Oct 14, 1974, and March 6
1¢
applications falsely
stated that
certal
es, mall
aed. The defendant gave
the 34-
; dresses
of the Sercer and Union caunty jos, but claimed ownership
of 1
‘buildings
on deveral eredit.card apolleations,
scvording 10 Une indiet
salary and receiving ered trem
75
As Parker. points out, removing the control/esc
keys from every terminal is ‘about as practical
Angtalling NX missiles on underground railroad:
under Nevada. It won't work, because there are
already over 3 million terminals in America, each
with an egcape and control key. And installing a
software filter for control/escpae characters is
a cheap fix too. Parker points out (and so do I)
that operating systens are so complex thet there
will always be some way of slipping the characters
around the filter and getting them to their
destination. The proper way to fix this problem
(from a cops point of view) would be to fix what-
ever aspect of the UNIX system allows the charact-
ers to let one workspace take over control of
another. Since this
idea
seems to have been aban-
doned by Parker, and since he also points out that
it would be possible to use this method on other
operating systems, I come to the conclusion that
the flaw ig not in the UNIX code itself, but in
the concept of time-sharing itself, I've read some
of Parker's work, he
isn't stupid. If there were
a foolproof way of fixing this problem he would
have found it by now.
So what does this mean? That we may be onto
the bignest security system break in history!
Almost any large computer is potentially vulner-
atle. But we need more information on how to do
this. “y information came from the LA Times. Tom
has @ copy of the article, and I'm sure he would
send a copy to anyone who is interested, but it
doesn't get too technical. It does mention two
sources of more technical data atout this. First
of
all, there was an article in Infoworld during
January about this (InfoWorld comes out weekly).
So far 1 haven't teen able to get a copy of this
issue. If you have or can get a4 copy of it, PLEASE
send it to me c/o TAP. The second source is fron
Parker at SRI. If you write to him on company
stationary, and eonvince him that you are a security
analyst or something similair, and give him a
legitimate sounding address, he will send you a
copy of his report on the subject, which tells
every detail.
His address is Donn Parker, SRI
International, Menlo Park CA, 94025. Please don't
write to him unless you have stationary and a
business sounding address,
and are sure you can
convince him that you have a need to know. If he
is deluged with requests for the report from phreaks,
he will stop sending then out. 7 don't have either
so I haven't been able to get the report. If you
manage to get a copy, please PIEASE send a copy to
me c/o TAP, Also, if you have any
knowledge of UNIX
systems, please write down whatever you know, sys-
tem structure, security formats, whatever, and send
it to me, as 1 don't know too much about UNIX,
As soon as I know how to do this I will tell every-
one in TAP, but I doubt I'l) be able to find out
uniess you all help me ty sending me whatever you
jo
know.
A Taxpayer Invents Ripoff
sar faire be ean
weer ne wahetwhes
Woot Senge
realestate